AWS::IAM::User Policy - Amazon CloudFormation
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

AWS::IAM::User Policy

Contains information about an attached policy.

An attached policy is a managed policy that has been attached to a user, group, or role.

For more information about managed policies, refer to Managed Policies and Inline Policies in the IAM User Guide.


To declare this entity in your Amazon CloudFormation template, use the following syntax:


{ "PolicyDocument" : Json, "PolicyName" : String }


PolicyDocument: Json PolicyName: String



The entire contents of the policy that defines permissions. For more information, see Overview of JSON policies.

Required: Yes

Type: Json

Update requires: No interruption


The friendly name (not ARN) identifying the policy.

Required: Yes

Type: String

Pattern: [\w+=,.@-]+

Minimum: 1

Maximum: 128

Update requires: No interruption


IAM User Policy

This example shows how the policy document is declared.


{ "PolicyName": "root", "PolicyDocument": { "Version": "2012-10-17", "Statement": [ { "Sid": "IamListAccess", "Effect": "Allow", "Action": [ "iam:ListRoles", "iam:ListUsers" ], "Resource": "*" } ] } }


PolicyName: root PolicyDocument: Version: 2012-10-17 Statement: - Sid: IamListAccess Effect: Allow Action: - 'iam:ListRoles' - 'iam:ListUsers' Resource: '*'

See also

  • PolicyDetail in the Amazon Identity and Access Management API Reference